A4 Refereed article in a conference publication
Patient Privacy in Differentially Private Diagnostic Models; 
Authors: Järv, Priit; Pahikkala, Tapio; Airola, Antti
Editors: Sivagnanam, Amutheezan; Slamanig, Daniel
Conference name: International Workshop on Security and Privacy Analytics
Publication year: 2026
Book title : IWSPA '26 : Proceedings of the 12th ACM International Workshop on Security and Privacy Analytics
First page : 10
Last page: 15
ISBN: 979-8-4007-2609-5
DOI: https://doi.org/10.1145/3806007.3810963
Publication's open availability at the time of reporting: Open Access
Publication channel's open availability : Open Access publication channel
Web address : https://doi.org/10.1145/3806007.3810963
Self-archived copy’s web address: https://research.utu.fi/converis/portal/detail/Publication/526899103
Self-archived copy's licence: CC BY
Self-archived copy's version: Publisher`s PDF
Differential privacy gives a theoretical guarantee against inferring the presence of a patient in the training data of a model. Patients can have multiple data records that are used as separate training inputs, but to apply differential privacy we must view the contribution of a patient as a single privacy unit. The main approaches are user level privacy that uses all records of the patient as the privacy unit, group privacy which simplifies computation by allowing each patient to have at most k records, and sample level privacy that requires each patient to contribute one record. Of these, sample level privacy is well supported by efficient deep learning libraries and can be adapted to group privacy. User level differential privacy in the medical domain remains poorly supported by software and, as a consequence, unexplored. We compare these three approaches in experiments with cardiovascular disease and melanoma datasets. We found that in case most patients contribute only a single data record, sample level privacy suffices. With all patients contributing multiple records, user level privacy performed best, because it avoids the limitations of the alternative approaches: restricting the number of examples per patient, or inaccurately assuming all patients have the same number of records in privacy accounting.
Downloadable publication This is an electronic reprint of the original article. |
Funding information in the publication:
This work was supported by Research Council of Finland (grant 358868).